CVE-2022-47946
MEDIUMLinux Kernel 5.10.x < 5.10.155 - Use-After-Free in io_sqpoll_wait_sq
Title source: llmDescription
An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attacker to crash the kernel, resulting in denial of service. finish_wait can be skipped. An attack can occur in some situations by forking a process and then quickly terminating it. NOTE: later kernel versions, such as the 5.15 longterm series, substantially changed the implementation of io_sqpoll_wait_sq.
References (3)
Core 3
Core References
Mailing List, Patch, Third Party Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=v5.10.161&id=0f544353fec8e717d37724d95b92538e1de79e86
Exploit, Mailing List, Third Party Advisory
https://www.openwall.com/lists/oss-security/2022/12/22/2
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/12/27/1
Scores
CVSS v3
5.5
EPSS
0.0037
EPSS Percentile
29.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (1)
linux/linux_kernel
5.10 - 5.10.155
Published
Dec 23, 2022
Tracked Since
Feb 18, 2026